Alerting

How to create an website monitoring alert?

Germaine1989
Engager

Hello,

I have some websites I monitor.
I want to receive an alert when a website is not available more than 15 minutes.
Can you help me create a query for that?

Labels (2)
0 Karma

GaetanVP
Contributor

Hello @gcusello,

I agree with you, just for my curiosity, would you setup the alert like this ?

GaetanVP_0-1665473552547.png

Thanks for your posts that I always enjoy to read !

Regards,
GaetanVP  

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @GaetanVP,

yes, it's correct.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Germaine1989,

I suppose that when your website is down you don't have any log from it, in this case you can create a simple alert

index=<your_index> host=<your_host>

to run every 10 minutes, the alert must fire if you don't have results.

If instead you continue to have logs from that host, you have to identify the logs that demonstarte that the log is up, and then insert this additional condition to the above search.

Ciao.

Giuseppe

Germaine1989
Engager
  • Thanks for you answer.

    I dont know what you mean with your_index
    I don't have any specific index for the Website Monitoring Add on.
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Germaine1989,

you surely archive the logs from the website in one or more indexes that I don't know: "<your_index>" means this or these index/es.

Ciao.

Giuseppe

 

0 Karma

Germaine1989
Engager

i have found something.

what can i set up as a condition?

Trigger Conditions

I want to trigger an alert when a website is failed more than 15 minutes.

Germaine1989_0-1665481813194.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

@Germaine1989,

as I said, you have to create a search that usually has results, and that the condition "results=0" is the firing condition.

then you can create the alert firing with the condition results=0.

in the search you have to define a time period of 15 minutes and schedule the alert every 15 minutes.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...